« Volver al listado

CVE-2023-53700

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

media: max9286: Fix memleak in max9286_v4l2_register()

There is a kmemleak when testing the media/i2c/max9286.c with bpf mock device:

kmemleak: 5 new suspected memory leaks (see /sys/kernel/debug/kmemleak)

max9286_v4l2_register() calls v4l2_ctrl_new_std(), but won't free the created v412_ctrl when fwnode_graph_get_endpoint_by_id() failed, which causes the memleak. Call v4l2_ctrl_handler_free() to free the v412_ctrl.

Detalles técnicos trazas, registros y código del informe original
unreferenced object 0xffff88810defc400 (size 256):
  comm "python3", pid 278, jiffies 4294737563 (age 31.978s)
  hex dump (first 32 bytes):
    28 06 a7 0a 81 88 ff ff 00 fe 22 12 81 88 ff ff  (.........".....
    10 c4 ef 0d 81 88 ff ff 10 c4 ef 0d 81 88 ff ff  ................
  backtrace:
    [<00000000191de6a7>] __kmalloc_node+0x44/0x1b0
    [<000000002f4912b7>] kvmalloc_node+0x34/0x180
    [<0000000057dc4cae>] v4l2_ctrl_new+0x325/0x10f0 [videodev]
    [<0000000026030272>] v4l2_ctrl_new_std+0x16f/0x210 [videodev]
    [<00000000f0d9ea2f>] max9286_probe+0x76e/0xbff [max9286]
    [<00000000ea8f6455>] i2c_device_probe+0x28d/0x680
    [<0000000087529af3>] really_probe+0x17c/0x3f0
    [<00000000b08be526>] __driver_probe_device+0xe3/0x170
    [<000000004382edea>] driver_probe_device+0x49/0x120
    [<000000007bde528a>] __device_attach_driver+0xf7/0x150
    [<000000009f9c6ab4>] bus_for_each_drv+0x114/0x180
    [<00000000c8aaf588>] __device_attach+0x1e5/0x2d0
    [<0000000041cc06b9>] bus_probe_device+0x126/0x140
    [<000000002309860d>] device_add+0x810/0x1130
    [<000000002827bf98>] i2c_new_client_device+0x359/0x4f0
    [<00000000593bdc85>] of_i2c_register_device+0xf1/0x110

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53700",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "66d8c9d2422da21ed41f75c03ba0685987b65fe0",
              "lessThan": "505ff3a0c5951684c3a43094ca4c1a74683d5681",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "66d8c9d2422da21ed41f75c03ba0685987b65fe0",
              "lessThan": "5897fe3ebe8252993579e1bee715ebfe5504e052",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "66d8c9d2422da21ed41f75c03ba0685987b65fe0",
              "lessThan": "724039e013b34f46344abdbf8c74e6a65a828327",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "66d8c9d2422da21ed41f75c03ba0685987b65fe0",
              "lessThan": "5e31213fa017c20ccc989033a5f4a626473aa2ca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "66d8c9d2422da21ed41f75c03ba0685987b65fe0",
              "lessThan": "8636c5fc7658c7c6299fb8b352d24ea4b9ba99e2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/i2c/max9286.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.173",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.99",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.16",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/i2c/max9286.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-22T14:15:44.547",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/505ff3a0c5951684c3a43094ca4c1a74683d5681",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5897fe3ebe8252993579e1bee715ebfe5504e052",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5e31213fa017c20ccc989033a5f4a626473aa2ca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/724039e013b34f46344abdbf8c74e6a65a828327",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8636c5fc7658c7c6299fb8b352d24ea4b9ba99e2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: max9286: Fix memleak in max9286_v4l2_register()\n\nThere is a kmemleak when testing the media/i2c/max9286.c with bpf mock\ndevice:\n\nkmemleak: 5 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\n\nunreferenced object 0xffff88810defc400 (size 256):\n  comm \"python3\", pid 278, jiffies 4294737563 (age 31.978s)\n  hex dump (first 32 bytes):\n    28 06 a7 0a 81 88 ff ff 00 fe 22 12 81 88 ff ff  (.........\".....\n    10 c4 ef 0d 81 88 ff ff 10 c4 ef 0d 81 88 ff ff  ................\n  backtrace:\n    [<00000000191de6a7>] __kmalloc_node+0x44/0x1b0\n    [<000000002f4912b7>] kvmalloc_node+0x34/0x180\n    [<0000000057dc4cae>] v4l2_ctrl_new+0x325/0x10f0 [videodev]\n    [<0000000026030272>] v4l2_ctrl_new_std+0x16f/0x210 [videodev]\n    [<00000000f0d9ea2f>] max9286_probe+0x76e/0xbff [max9286]\n    [<00000000ea8f6455>] i2c_device_probe+0x28d/0x680\n    [<0000000087529af3>] really_probe+0x17c/0x3f0\n    [<00000000b08be526>] __driver_probe_device+0xe3/0x170\n    [<000000004382edea>] driver_probe_device+0x49/0x120\n    [<000000007bde528a>] __device_attach_driver+0xf7/0x150\n    [<000000009f9c6ab4>] bus_for_each_drv+0x114/0x180\n    [<00000000c8aaf588>] __device_attach+0x1e5/0x2d0\n    [<0000000041cc06b9>] bus_probe_device+0x126/0x140\n    [<000000002309860d>] device_add+0x810/0x1130\n    [<000000002827bf98>] i2c_new_client_device+0x359/0x4f0\n    [<00000000593bdc85>] of_i2c_register_device+0xf1/0x110\n\nmax9286_v4l2_register() calls v4l2_ctrl_new_std(), but won't free the\ncreated v412_ctrl when fwnode_graph_get_endpoint_by_id() failed, which\ncauses the memleak. Call v4l2_ctrl_handler_free() to free the v412_ctrl."
    }
  ],
  "lastModified": "2026-06-17T06:45:54.700",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}